Show the Table of Contents
Administration & Maintenance
Instant TROUBLESHOOTING
Here are just a few quick things to check if your Luna SA experience is
not quite as smooth as you had hoped:
- Ensure that the date and time are set correctly
(this is the number one, most frequent, cause of difficulty).
- Check that NTLS is bound to the correct Ethernet
port (it must be bound to a port if it is to work, and of course that
port must be the one that is connected for NTLS).
- Ensure that the client is registered with the
correct ip/hostname (or that you spelled it correctly, didn't accidentally
transpose any characters, used only valid characters, etc.).
- Ensure that the client is given access to the
correct partition (again, be sure that it is spelled correctly; be careful
of similarly named or numbered partitions).
- Check the output of the syslog for any information
on potential problems (syslog tail).
- If you see an apparent 'hang' condition, connect
and check the PED - it may be waiting for a PED action.
- Check if you allowed the PED to time out, or if you started a command that needed PED action while the PED was not connected. You will need to re-issue the failed command after re-inserting the token, and pay attention to the PED.
- Ensure that the sysconf regenCert command was
properly executed (with the IP address, if using IP mode)
- If RSA signing seems slow, check the Capabilities
and Policies to ensure that Confirmation (policy #29) is switched off
- if your security policy demands that signing operations must be verified
on the HSM, then expect almost a 50% performance reduction
- If you perform a Restore from Backup operation and some or all of the objects are shown with an error message like "LUNA_RET_SM_ACCESS_DOES_NOT_VALIDATE", you might have interrupted the restore operation (even a partition showContents command could have this effect). Re-issue the Restore command, ensuring that no other commands are run against the partition while the operation is in progress - if other persons might be using their own ssh sessions to access the appliance, it might be best to disconnect the network cable[s] and perform your restore operation from the local (serial) console.
REMOTE PED
If you find that Windows fails to detect Luna PED, especially if you have disconnected and reconnected the PED's USB cable to your computer there could be two problems:
- Luna PED is powered by PED port connection only when it is connected to a Luna HSM. When Luna PED is used for Remote PED, it is connected to a computer USB port, which does not have the same electrical characteristics as the PED port on a Luna HSM. The PED switches on, but might not receive sufficient power to operate.
If you are connecting locally, always connect the PED to the Luna HSM.
If you are connecting to a computer for use as a Remote PED server, always connect the PED power supply in addition to the USB connection.
Show the Table of Contents